CVE-2025-10891: Integer overflow in V8
Chromium: CVE-2025-10891 Integer overflow in V8
Other sources
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.0.7339.207 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 140.0.7339.207 - Upgrade
Upgrade
Microsoft Edge (Chromium-based)to a version that resolves this vulnerability.Fixed in 140.0.7339.207
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10891?
CVE-2025-10891 has a high severity rating due to the potential for heap corruption exploitation.
How do I fix CVE-2025-10891?
To fix CVE-2025-10891, update Google Chrome to version 140.0.7339.207 or later.
What does CVE-2025-10891 affect?
CVE-2025-10891 affects Google Chrome versions prior to 140.0.7339.207.
What type of vulnerability is CVE-2025-10891?
CVE-2025-10891 is an integer overflow vulnerability in V8.
Can CVE-2025-10891 be exploited remotely?
Yes, CVE-2025-10891 can potentially be exploited remotely via a crafted HTML page.